NSE4 Security Profiles Practice Question
An administrator wants to configure a DNS filter to block access to known malicious domains and also enforce safe search on search engines. Which THREE settings are required in the DNS filter profile? (Choose three.)
⚠ Common exam trap
Many candidates confuse the DNS sinkhole IP address (a response action) with a required setting for blocking, or they think external DNS servers must be specified in the profile, when in fact the DNS filter profile uses the FortiGate's system DNS settings by default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add entries to the static domain blocklist
Adding entries to the static domain blocklist allows the administrator to manually specify known malicious domains that should be blocked regardless of FortiGuard category ratings. This provides a hard-coded block for domains that may not yet be categorized or that the administrator wants to ensure are always blocked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add entries to the static domain blocklist
Why this is correct
Adding entries to the static domain blocklist within a DNS filter profile is correct because it allows you to manually specify exact domain names to always block, independent of FortiGuard categorization. This is useful for domains that are known threats or unwanted but may not yet be classified by FortiGuard, or for enforcing custom corporate policy. The blocklist takes precedence over category-based filtering, ensuring these domains are always denied.
- ✓
Select 'Redirect to safe search' for search engines
Why this is correct
Selecting 'Redirect to safe search' for search engines is correct because it forces the use of safe search features on supported engines like Google, Bing, and YouTube by rewriting DNS responses for those sites to a safe-search enforcement IP. This ensures that even if a user manually changes SafeSearch settings, the DNS filter will override it at the network level. It is a complementary feature that restricts content on search engine results without blocking the entire domain.
- ✗
Configure a DNS sinkhole IP address
Why it's wrong here
Configuring a DNS sinkhole IP address is not required for simply blocking a domain, as basic blocking can be achieved by returning NXDOMAIN or dropping the query. A sinkhole is an optional mechanism that redirects blocked domains to a specified IP address, typically a server that displays a warning page or captures the client's connection attempt, but it is not a prerequisite for enforcement. Even though it's a common feature of DNS filtering, the administrator can block domains without defining a sinkhole.
- ✗
Specify external DNS servers for resolution
Why it's wrong here
Specifying external DNS servers for resolution is a system-wide configuration handled under Network > DNS, not within the DNS filter profile itself. DNS filter profiles enforce policies on DNS queries that the FortiGate receives and forwards; the choice of upstream DNS server does not affect the filtering logic or the ability to block specific domains. This option is therefore unrelated to the task of blocking a particular domain like 'ac.example'.
- ✓
Enable DNS filtering based on FortiGuard categories
Why this is correct
Enabling DNS filtering based on FortiGuard categories is correct because it lets you block entire classes of malicious or inappropriate domains, such as malware, phishing, or adult content, using FortiGuard's continuously updated database. This method works by checking the domain against FortiGuard's category classification for every DNS query. It complements a static blocklist by providing dynamic protection against newly discovered threats and broad policy enforcement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.